Storage Controller Software Tampering Tests for Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The reliability of storage systems is compromised due to the inability of users to verify the correct functioning of authenticity verification functions during software activation, which can lead to potential tampering and degradation of system integrity.
Innovation Solution
A system and method for performing tampering verification in the activation of software executed by a storage controller, involving a management system that stores verification software, allows users to tamper with parts of the software, and presents the verification results to ensure the secure boot function operates correctly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure boot function is implemented to verify software authenticity, then software integrity is improved, but user ability to verify correct functioning of verification function is lost
Solution Approach 1:
The patent creates a copy of the verification software called 'verification of verification software' that can be independently tested. This copy includes test data and assumed test results that allow users to verify the verification function's correctness without compromising the original secure boot mechanism. The copying principle enables users to have a testable replica while maintaining the integrity of the production software.
Solution Approach 2:
The patent performs preliminary testing of the verification software before actual software activation. By pre-installing the verification of verification software and pre-preparing test data, the system allows users to advance test the verification function in advance. This preliminary action ensures the verification mechanism is working correctly before it is needed for actual software activation, resolving the contradiction by enabling verification capability without affecting production integrity.
2Reliability
If verification software is installed in storage controller, then authenticity verification is improved, but user ability to test verification function is lost
Solution Approach 1:
The patent segments the verification software into two distinct parts: the original verification software for production use and the verification of verification software for testing purposes. This segmentation allows the verification function to be separated into a testable copy while maintaining the original in the storage controller. Users can interact with and test the segmented verification copy without affecting the production verification software, thereby improving ease of operation while maintaining reliability.
3Reliability
If storage controller activates verification software, then software security is improved, but user transparency about verification status is reduced
Solution Approach 1:
The patent implements a feedback mechanism where the verification of verification software provides test results to users about the verification function's correctness. The system feeds back information about whether the verification software is working properly, allowing users to transparently understand the verification status. This feedback loop resolves the contradiction by providing verification status information without compromising the security of the activation process, as the feedback comes from a separate testable copy rather than the production verification software itself.
Data Source
AI summary
A system acquires verification software to be executed by a storage controller. The verification software includes a program for detecting tampering in the verification software. The system tampers with a part of the verification software according to an instruction from a user. The system installs the verification software tampered with at the part in the storage controller and activates the verification software. The system presents, to the user, the result of verification of tampering by the verification software which has been received from the storage controller.


